<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
><channel><title>JaypeeOnline &#187; security-flaw</title> <atom:link href="http://jaypeeonline.net/tag/security-flaw/feed/" rel="self" type="application/rss+xml" /><link>http://jaypeeonline.net</link> <description>Technology, Blogging News, WordPress Theme and Plugin Reviews, Tips and Tricks</description> <lastBuildDate>Mon, 21 May 2012 03:17:06 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=</generator> <item><title>PayPal Patches iPhone App Flaw</title><link>http://jaypeeonline.net/paypal/paypal-patch-iphone-app-flaw/</link> <comments>http://jaypeeonline.net/paypal/paypal-patch-iphone-app-flaw/#comments</comments> <pubDate>Fri, 05 Nov 2010 00:54:23 +0000</pubDate> <dc:creator>Jaypee Habaradas</dc:creator> <category><![CDATA[Mobile]]></category> <category><![CDATA[Paypal]]></category> <category><![CDATA[app store]]></category> <category><![CDATA[CNET]]></category> <category><![CDATA[iphone]]></category> <category><![CDATA[iphone app]]></category> <category><![CDATA[iphone app flaw]]></category> <category><![CDATA[man-in-the-middle attack]]></category> <category><![CDATA[paypal iphone app]]></category> <category><![CDATA[paypal iphone app flaw]]></category> <category><![CDATA[security-flaw]]></category><guid
isPermaLink="false">http://jaypeeonline.net/?p=9208</guid> <description><![CDATA[While updating my iPhone apps earlier today, I noticed an update for the PayPal iPhone app &#8211; version 3.0.1. When I read the changelog or update details, it mentioned that the version included an important security update. It didn&#8217;t specify what type of security update so I decided to do a little research. Found out [...]]]></description> <content:encoded><![CDATA[<p><img
src="http://maxcdn.jaypeeonline.net/images/paypal_iphone.png" alt="PayPal iPhone App" /></p><p>While updating my <a
href="http://jaypeeonline.net/gadgets/iphone-3gs/">iPhone</a> apps earlier today, I noticed an update for the <strong>PayPal iPhone app</strong> &#8211; version 3.0.1. When I read the changelog or update details, it mentioned that the version included an important security update. It didn&#8217;t specify what type of security update so I decided to do a little research. Found out from CNET that the update was a <a
href="http://news.cnet.com/8301-27080_3-20021730-245.html">patch for a security hole</a> in the iPhone app.</p><p>The now patched security flaw could have allowed malicious users to do a &#8220;<strong>man-in-the-middle</strong>&#8221; attack, tricking users into thinking that they&#8217;re accessing the real <strong>PayPal</strong> site when actually they aren&#8217;t and intercept transaction data sent between the iPhone and a <strong>Wi-Fi hotspot</strong>. This can happen when PayPal users access their account using an <strong>unsecured Wi-Fi network</strong>.</p><p>Aside from patching the security flaw on the iPhone app, <strong>PayPal</strong> has also announced that it will provide a <strong>100% reimbursement</strong> for any fraudulent activity caused by the flaw.</p><p>If you have the <strong>PayPal</strong> app on your iPhone, make sure that you immediately upgrade to the latest version. If you haven&#8217;t, do not access your account until you&#8217;ve installed the update. And just to be sure, avoid or never access your PayPal or bank account on your mobile device over an unsecured Wi-Fi network.</p><p>The latest version of the <strong>Paypal iPhone app</strong> is now available in the <a
href="http://itunes.apple.com/us/app/paypal/id283646709">App Store</a>.</p><p>[via <a
href="http://news.cnet.com/8301-27080_3-20021730-245.html">CNET News</a>]</p><div
id="crp_related"><ul><li><a
href="http://jaypeeonline.net/paypal/paypal-debit-card/" rel="bookmark" class="crp_title">PayPal Debit Card</a></li><li><a
href="http://jaypeeonline.net/paypal/new-paypal-debit-card/" rel="bookmark" class="crp_title">New PayPal Debit Card</a></li><li><a
href="http://jaypeeonline.net/paypal/paypal-phishing-email/" rel="bookmark" class="crp_title">PayPal Phishing Email</a></li><li><a
href="http://jaypeeonline.net/software/ios-4-3-3-software-update/" rel="bookmark" class="crp_title">iOS 4.3.3 Software Update</a></li><li><a
href="http://jaypeeonline.net/freeware/apple-itunes-10-1-2/" rel="bookmark" class="crp_title">Apple Releases iTunes 10.1.2 &#8211; Bug Fixes &#038; CDMA iPhone Support</a></li><li><a
href="http://jaypeeonline.net/wordpress/wordpress-for-iphoneipad-version-2-6-now-available/" rel="bookmark" class="crp_title">WordPress for iPhone/iPad Version 2.6 Now Available</a></li><li><a
href="http://jaypeeonline.net/freeware/apple-ios-4-3/" rel="bookmark" class="crp_title">iOS 4.3 Now Available For Download</a></li><li><a
href="http://jaypeeonline.net/gadgets/iphone-3gs/" rel="bookmark" class="crp_title">Early Christmas Gift</a></li><li><a
href="http://jaypeeonline.net/mobile/google-iphone-app-now-available/" rel="bookmark" class="crp_title">Google+ iPhone App Now Available</a></li><li><a
href="http://jaypeeonline.net/weekend-roundup/weekend-roundup-104/" rel="bookmark" class="crp_title">Weekend Roundup #104</a></li></ul></div>]]></content:encoded> <wfw:commentRss>http://jaypeeonline.net/paypal/paypal-patch-iphone-app-flaw/feed/</wfw:commentRss> <slash:comments>2</slash:comments> </item> <item><title>Firefox + IE = Security Flaw?</title><link>http://jaypeeonline.net/firefox/firefox-ie-security-flaw/</link> <comments>http://jaypeeonline.net/firefox/firefox-ie-security-flaw/#comments</comments> <pubDate>Thu, 12 Jul 2007 01:39:32 +0000</pubDate> <dc:creator>Jaypee Habaradas</dc:creator> <category><![CDATA[Firefox]]></category> <category><![CDATA[Internet]]></category> <category><![CDATA[internet-explorer]]></category> <category><![CDATA[Microsoft]]></category> <category><![CDATA[Mozilla]]></category> <category><![CDATA[security-flaw]]></category><guid
isPermaLink="false">http://jaypeeonline.net/?p=317</guid> <description><![CDATA[This is the first time I&#8217;ve heard of a security flaw that&#8217;s caused or involves two browsers. Most of the time, known security flaws are found in Internet Explorer and sometimes in Firefox. But this time it involves both browsers. At first, security researchers laid the blame for the latest zero-day exploit on Microsoft&#8217;s Internet [...]]]></description> <content:encoded><![CDATA[<p></p><p><img
src="http://maxcdn.jaypeeonline.net/images/firefox_ie.jpg" alt="FIrefox and Internet Explorer" /></p><p>This is the first time I&#8217;ve heard of a security flaw that&#8217;s caused or involves two browsers. Most of the time, known security flaws are found in Internet Explorer and sometimes in Firefox. But this time it involves both browsers.</p><p>At first, security researchers laid the blame for the <a
href="http://larholm.com/2007/07/10/internet-explorer-0day-exploit/">latest zero-day exploit</a> on Microsoft&#8217;s Internet Explorer. Later on, they found out that the <a
href="http://secunia.com/advisories/25984/">problem was with Firefox 2.0+</a> and that it was also vulnerable.</p><p><strong>From CNet&#8217;s News Blog:</strong></p><blockquote><p>Users could face a &#8220;highly critical&#8221; risk if they have both IE and Firefox version 2.0, or later, loaded on their computer. The trouble begins when browsing a malicious site while using IE and it registers a &#8220;firefoxurl://&#8221; URI (uniform resource identifier) handler, which allows the browser to interact with specific resources on the Web. As a result, users may find their systems remotely compromised.</p></blockquote><p>Researchers say it&#8217;s a little bit of both. But from what I understand, even if you have both browsers installed on your computer but only use Firefox for browsing, then you won&#8217;t be at risk. If you&#8217;re running both browsers on your computer, make sure to check for security updates and install them right away.</p><p>One advantage of using Ubuntu/Linux or a Mac is that you don&#8217;t get to worry about these kinds of issues. I&#8217;m glad I <a
href="http://jaypeeonline.net/blog/joining-the-linux-bandwagon/">joined the Linux bandwagon</a> and installed Ubuntu on my machine. Even if you&#8217;re still using Windows, you can avoid this if you stop using IE and rather use Firefox, Flock or Opera.<br
/><script type="text/javascript"><!--
google_ad_client = "pub-8462667317196834";
google_ad_output = "textlink";
google_ad_format = "ref_text";
google_cpa_choice = "CAAQwaT2_gEaCK4YeWxdsHieKLGsuIEBMAA";
google_ad_channel = "";
//-->
</script><br
/><script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>.</p><p>Read the full story: <a
href="http://news.com.com/8301-10784_3-9741435-7.html?tag=cnetfd.mt">Firefox and IE together brew up security trouble</a></p><div
id="crp_related"><ul><li><a
href="http://jaypeeonline.net/firefox/kill-bills-browser/" rel="bookmark" class="crp_title">Kill Bill&#8217;s Browser</a></li><li><a
href="http://jaypeeonline.net/paypal/another-paypal-phishing-email/" rel="bookmark" class="crp_title">Another PayPal Phishing Email</a></li><li><a
href="http://jaypeeonline.net/internet/ie7-pro-ultimate-add-on-for-internet-explorer/" rel="bookmark" class="crp_title">IE7 Pro: Ultimate Add-On for Internet Explorer</a></li><li><a
href="http://jaypeeonline.net/firefox/firefox-6th-birthday/" rel="bookmark" class="crp_title">Happy 6th Birthday Mozilla Firefox!</a></li><li><a
href="http://jaypeeonline.net/firefox/mozilla-plugin-check/" rel="bookmark" class="crp_title">Mozilla Plugin Check For Everyone</a></li><li><a
href="http://jaypeeonline.net/firefox/mozilla-release-firefox-3-6-13-security-update/" rel="bookmark" class="crp_title">Mozilla Release Firefox 3.6.13 Security Update</a></li><li><a
href="http://jaypeeonline.net/internet/internet-explorer-9/" rel="bookmark" class="crp_title">How Do You Like Internet Explorer 9?</a></li><li><a
href="http://jaypeeonline.net/internet/internet-explorer-6-countdown/" rel="bookmark" class="crp_title">The Internet Explorer 6 Countdown</a></li><li><a
href="http://jaypeeonline.net/blogging/pingomatic-gets-a-makeover/" rel="bookmark" class="crp_title">Ping-O-matic Gets a Makeover</a></li><li><a
href="http://jaypeeonline.net/internet/safari-4-browsing-made-beautiful-and-smart/" rel="bookmark" class="crp_title">Safari 4: Browsing Made Beautiful. And Smart.</a></li></ul></div>]]></content:encoded> <wfw:commentRss>http://jaypeeonline.net/firefox/firefox-ie-security-flaw/feed/</wfw:commentRss> <slash:comments>13</slash:comments> </item> <item><title>WordPress Update</title><link>http://jaypeeonline.net/wordpress/test/</link> <comments>http://jaypeeonline.net/wordpress/test/#comments</comments> <pubDate>Sun, 07 Jan 2007 05:02:18 +0000</pubDate> <dc:creator>Jaypee Habaradas</dc:creator> <category><![CDATA[WordPress]]></category> <category><![CDATA[FeedBurner]]></category> <category><![CDATA[security-flaw]]></category> <category><![CDATA[updated]]></category> <category><![CDATA[wordpress-2.0.7]]></category><guid
isPermaLink="false">http://jaypeeonline.net/?p=109</guid> <description><![CDATA[Updated: 01/15/07 Just 10 days after version 2.0.6 was released, WordPress released version 2.0.7 to address a security vulnerability that can be caused by certain PHP versions and also to fix the Feedburner issues found in 2.0.6. You don&#8217;t have to update all of your WordPress files, only these files: * wp-admin/inline-uploading.php * wp-admin/post.php * [...]]]></description> <content:encoded><![CDATA[<p><strong>Updated: 01/15/07</strong></p><p>Just 10 days after version 2.0.6 was released, <a
href="http://wordpress.org/development/2007/01/wordpress-207/trackback/">WordPress released version 2.0.7</a> to address a security vulnerability that can be caused by certain PHP versions and also to fix the Feedburner issues found in 2.0.6.</p><p>You don&#8217;t have to update all of your WordPress files, only these files:</p><p>* wp-admin/inline-uploading.php<br
/> * wp-admin/post.php<br
/> * wp-includes/classes.php<br
/> * wp-includes/functions.php<br
/> * wp-settings.php<br
/> * wp-includes/version.php</p><p>I&#8217;ve already upgraded WordPress to 2.0.7 earlier.</p><p>Download <a
href="http://wordpress.org/development/2007/01/wordpress-207/">WordPress 2.0.7</a></p><p>I&#8217;ve upgraded WordPress to version 2.0.6. The reason for this is I wanted to make sure that any existing security bugs would be fixed. &#8220;Better safe than sorry&#8221;, is what they say. This latest version fixes over 50 other bugs from the previous version. Also, if you are using Feedburner and decide to upgrade to 2.0.6 and  you would also need this <a
href="http://weblogtoolscollection.com/archives/2007/01/06/wordpress-fix-for-feedburner/">fix</a>.</p><div
id="crp_related"><ul><li><a
href="http://jaypeeonline.net/wordpress/wordpress-222-2011-security-upgrades/" rel="bookmark" class="crp_title">WordPress 2.2.2 &#038; 2.0.11 Security Upgrades</a></li><li><a
href="http://jaypeeonline.net/wordpress/wordpress-265/" rel="bookmark" class="crp_title">WordPress 2.6.5</a></li><li><a
href="http://jaypeeonline.net/wordpress/wordpress-223-security-release/" rel="bookmark" class="crp_title">WordPress 2.2.3 Security Release</a></li><li><a
href="http://jaypeeonline.net/wordpress/wordpress-3-1-2-security-update/" rel="bookmark" class="crp_title">WordPress 3.1.2 Security Update</a></li><li><a
href="http://jaypeeonline.net/wordpress/wordpress-3-3-2-wordpress-3-4-beta-3-released/" rel="bookmark" class="crp_title">WordPress 3.3.2 &#038; WordPress 3.4 Beta 3 Released</a></li><li><a
href="http://jaypeeonline.net/wordpress/wordpress-206/" rel="bookmark" class="crp_title">WordPress 2.0.6</a></li><li><a
href="http://jaypeeonline.net/wordpress/wordpress-3-1-3-security-update-wordpress-3-2-beta-2-released/" rel="bookmark" class="crp_title">WordPress 3.1.3 Security Update &#038; WordPress 3.2 Beta 2 Released</a></li><li><a
href="http://jaypeeonline.net/wordpress/wordpress-211-dangerous-download/" rel="bookmark" class="crp_title">WordPress 2.1.1 &#8211; Dangerous Download</a></li><li><a
href="http://jaypeeonline.net/wordpress/wordpress-233/" rel="bookmark" class="crp_title">WordPress 2.3.3</a></li><li><a
href="http://jaypeeonline.net/wordpress/upgraded-to-wordpress-221/" rel="bookmark" class="crp_title">Upgraded To WordPress 2.2.1</a></li></ul></div>]]></content:encoded> <wfw:commentRss>http://jaypeeonline.net/wordpress/test/feed/</wfw:commentRss> <slash:comments>1</slash:comments> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk
Page Caching using disk (enhanced) (User agent is rejected)
Database Caching 6/14 queries in 0.110 seconds using disk
Object Caching 1009/1027 objects using disk
Content Delivery Network via maxcdn.jaypeeonline.net

Served from: jaypeeonline.net @ 2012-05-27 07:47:58 -->
